TrustedVolumes Hacker Returns $2 Million, Keeps $2 Million as Bounty
TrustedVolumes Hacker Returns $2 Million, Retains Another $2 Million
A hacker involved in the TrustedVolumes breach has returned 1,122 ETH, which is valued at approximately $2 million, while keeping another $2 million as a self-declared bounty.
Background of the Incident
In May, an attack on TrustedVolumes resulted in a loss of around $5.87 million. The attacker targeted a custom request-for-quote (RFQ) swap proxy managed by TrustedVolumes, leading to the illicit withdrawal of funds.
Details on the Return and Retained Funds
The recent Ethereum transfer signifies a partial recovery from the May incident. However, the hacker’s retained bounty of $2 million is equal to the funds returned. At the time of the transfer, ETH prices had fallen since the initial breach, leading to a reduced total value of recouped assets.
TrustedVolumes’ Response
As of now, TrustedVolumes has not formally accepted the terms proposed by the attacker regarding the bounty. The company previously disclosed that the total loss from the exploit had reached roughly $6.7 million, which is higher than initial estimates. Efforts to recover the stolen assets included offering terms for a vulnerability bounty.
Details of the Attack
Following the attack, analysis by Blockaid revealed the extraction of a variety of assets including 1,291.16 WETH, 206,282 USDT, 16.939 WBTC, and 1.27 million USDC. After the hack, these assets were reportedly consolidated, and the attacker managed to convert them into approximately 2,513 ETH.
Technical Vulnerability
The exploit was linked to deficiencies in the RFQ proxy’s programming, which lacked necessary access controls, allowing the perpetrator to register an address that could create seemingly valid transactions. This issue was identified by Verichains, who highlighted a mismatch in authorization methods.
Conclusion
This incident underscores the significance of evaluating security measures in smart contract systems to prevent future occurrences. The ongoing dialogue between TrustedVolumes and the attacker may influence the recovery process.
Source: crypto.news